Sep 16, 2024
sudo apt-get update and sudo apt-get install volatility.volatility command to access help menu and commands.
image info to identify the appropriate profile for the memory dump.pslist and pstree to list processes and identify hidden processes.consoles plugin to view command history of cmd.exe.dump files to extract files from memory; evaluate registry and environment variables.